Logo
vulnerabilityCVE-2026-64835
Name
CVE-2026-64835
Source
NVD ( link)Debian ( link)
Description
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Exploitable

Vulnerability Ratings#


8.7
CVSSv4
8.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Exploitable
buildroot
master
6.1.5
Exploitable
openwrt
master
6.1.4-r2
Exploitable
yocto
kirkstone
5.0.3
Exploitable
yocto
master
8.1.2
Exploitable
yocto
scarthgap
6.1.4
Exploitable